
The Cybersecurity company Threatfactor has discovered 12 Android applications, which can steal the data of Russian banking applications. Among the vulnerable were applications from Sberbank, Tinkoff-Bank, Uralsib, Mail Bank and OTP Bank. Malicious applications are masked for scanners of documents and QR codes. About this writes "Kommersant".
Wed to Yandex.Zen CR on Instagram SR in TelegramExperts identified three groups of malicious applications. One of them is aimed at Russia - Anatsa. Applications of this group were installed 200 thousand times, including the QR -codes scanner from the publisher of QRBARBODE LDC. This application was installed more than 50 thousand times.
Applications do not cause suspicions of users. The program asks to download "Update" and provide permission to install unknown applications. Under the guise of updating, a malicious code is loaded, which then requests permission to provide full access to the phone. Due to the fact that the virus is loaded separately from the application, it undergoes checks when publishing at the Play Market.
Threatfactor experts also note that malicious applications can extract passwords and codes of two-factor authentication delivered through SMS messages, record pressing on a virtual keyboard and take screenshots.
